{"repo":"NeilJed/aws-sso-credentials","free":true,"listed":false,"github":"https://github.com/NeilJed/aws-sso-credentials","clone":"git clone https://github.com/NeilJed/aws-sso-credentials.git","description":"A simple Python tool to get short-term access tokens for CLI/Boto3 operations when using AWS SSO","language":"Python","stars":52,"topics":["aws","aws-sso","credentials","authentication","sso","sso-client","boto3"],"license":"MIT","category":"auth-billing-email","readme_excerpt":"aws-sso-credentials About aws-sso-credentials - A simple Python tool to simplify getting short-term credential tokens for CLI/Boto3 operations when using AWS SSO. Uses standard AWS CLI configuration files and allows easy swapping between roles/accounts. Motivation In my organisation we use various CLI/Boto3 based tools with AWS. We have several accounts/roles and need a way to handle MFA, switch between accounts/roles, grab temporary session credentials and make sure they're up to date. To this end our go-to tool of choice was Limes. We switched to using AWS SSO linked to our Azure AD to centralise user management. This works great for Single-Sign-On and the new AWS CLI v2 supports AWS SSO natively. However, getting temporary credentials for use with Boto3 based apps, especially one that doesn't support profiles was a pain involving copying credentials from a web portal, exporting environment variables and a lot of error prone manual steps. This script is a quick work around to give us something functional that fits with our way of working until something better comes along. Maybe it works for you too. How it works This tool performs the SSO login itself via Boto3, caches the resulting SSO credentials (in the same location the AWS CLI uses), then makes Boto3 calls to retrieve the temporary credentials for the relevant account/role you want. For sso session -based profiles it logs in via PKCE (opens your browser, no code to type); legacy sso start url -based profiles use the d","default_branch":null,"files":null,"tree":[],"storefront":"/r/NeilJed","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/NeilJed/aws-sso-credentials/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}